T1584.004 — Server
T1584.004: Server
MITRE ATT&CK® Enterprise technique
| Tactics | Resource Development |
| Platforms | PRE |
| Permissions required | — |
| Version | 1.2 |
| Parent technique | T1584 |
Description
Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control.(Citation: TrendMicro EarthLusca 2022) Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.
Adversaries may also compromise web servers to support watering hole operations, as in Drive-by Compromise, or email servers to support Phishing operations.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1584/004
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/